WinXP SP3 hangs on boot

1

1_of_B0rg

Today I found that my Toshiba Satellite 1905-S303, running WinXP SP3, doesn't
show the Username login window after the Windows logo appears. It's just a
blue screen desktop with my cursor; desktop and icons don't load at all.
Other symptoms: although it's a laptop, the touchpad stopped working. Hitting
Ctrl-Alt-Delete doesn't work and I have to hit the power button to shut it
off and start over.

I've tried pushing F2 and F12 during the Win logo but I still end up at the
blue screen (Note it's not the "Blue Screen of Death" as there're no error
messages.) The only reason I can still work is thanks to Safe Mode, hitting
F8 twice. While in Safe Mode I tried to use System Restore for the last point
before everything went bonkers (9 days ago) but it couldn't restore. My
screen reso is reduced to 640x480 and I must use the arrow and Tab keys to do
everything!

Possible causes for the problem? I ran AVG Anti-Spyware 7.5 yesterday and
deleted some cookies. Then uninstalled AVG after it finished. I also d/l a
Win update from MS (yes it was official).

**I just d/l the SmitfraudFix program that was suggested by Randem for
another problem similar to my own. Would this help any?

Additional info:
I pasted below two of the errors from Event Viewer if that will help.

-----
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 12/21/2008
Time: 1:41:24 PM
User: NT AUTHORITY\SYSTEM
Computer: USS-RUSHMORE
Description:
DCOM got error "This service cannot be started in Safe Mode" attempting to
start the service EventSystem with arguments "" in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

For more information, see Help and
Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 12/21/2008
Time: 1:41:24 PM
User: NT AUTHORITY\SYSTEM
Computer: USS-RUSHMORE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to
start the service EventSystem with arguments "" in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
 
1

1_of_B0rg

Many thanks Ron! I owe you one =)

I followed the instructions (no clean-boot needed, just ran the Sigverif
utility) and found a dozen files. 11 were legit, one happened to be a virus.

According to
http://www.symantec.com/security_response/writeup.jsp?docid=2008-091809-0911-99&tabid=2
it was a rootkit trojan also known as Tdstealth. For me it showed up as
"tdsspqlt.sys" Moved it out of my System32 folder and everything is back to
normal. In fact my System Restore, which was on the fritz for about 2 months,
is working again.

Thanks again
 
R

Ron Badour

Thanks for the feedback. The clean boot technique often works wonders :)

--
Regards

Ron Badour
MS MVP
Windows Desktop Experience
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top